IP Library Granted Patent US 7,774,839
Granted Patent B2
US 7,774,839 · App. 10/701,157 · Granted Aug 10, 2010

Feedback mechanism to minimize false assertions of a network intrusion

Assignee: Riverbed Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,774,839
App. No.
10/701,157
Granted
Aug 10, 2010
Kind
B2
Abstract

A graphical user interface for an intrusion detection system is described. The graphical user interface includes a field that depicts a summary of anomalies identified as part of a event that is detected in a network, the summary indicating event severity details of the event and an alert action region including a control to permit a user to snooze future alerts related to the event in the summary for a period of time.

Claims (42)

1. A graphical user interface rendered on a display associated with an intrusion detection system, the graphical user interface comprising:

a field that depicts a summary of anomalies identified as part of an event that is detected in a network, the summary indicating event severity details of the event; and

an alert action region including a control to permit a user to snooze future alerts related to the event in the summary for a period of time.

2. The graphical user interface of claim 1 wherein the snooze control feature is selected based on event types and roles of hosts.

3. The graphical user interface of claim 1 further comprising:

a control to allow a user to clear an alert if the alert appears on an overview page that provides an operator with an aggregated view of network status.

4. The graphical user interface of claim 3 wherein an event details region of the graphical user interface depicts anomalies that were used to classify the event.

5. The graphical user interface of claim 1 wherein details of events include values of source, destination, and protocol that caused an event to be raised.

6. The graphical user interface of claim 1 wherein event severity is coded by an indicia.

7. The graphical user interface of claim 1 wherein the interface includes a control to clear a selected alert.

8. The graphical user interface of claim 1 wherein the interface includes a details control that allows a user to observe details about a selected anomaly.

9. The graphical user interface of claim 1 wherein the details control presents a list of IP addresses to which a host attempted to connect to.

10. A method comprises:

providing an operator with a list of events identified by an intrusion detection system, within the list of events being information indicating event severity, with event severity determined for an event, by the event having a percentage relationship to an established threshold for issuing an event notification;

displaying details of a selected one of the events to a user; and

providing on a graphical user interface a snooze control to allow a user to snooze future alerts related to the selected event.

11. The method of claim 10 the snooze control allows an event to be snoozed for a fixed period of time.

12. The method of claim 10 wherein the snooze control is for selected event types and roles.

13. The method of claim 10 further comprising:

clearing a selected alert from the list of events.

14. The method of claim 13 further comprising:

displaying anomalies that were used to classify the event.

15. The method of claim 14 further comprising:

displaying event details that indicate historically normal operating conditions of a host and current operating conditions of a host to allow the operator to take an appropriate action.

16. The method of claim 15 wherein one of the operating conditions displayed is normal and current connection rates of the host.

17. The method of claim 15 wherein the type of events include worm propagation, unauthorized access, denial of service attacks, and historical anomaly.

18. The method of claim 10 further comprising:

displaying event details including destination and source fields populated with IP addresses and role classification of the host in the network.

19. The method of claim 10 further comprising:

displaying actions taken by the operator for the particular event.

20. The method of claim 10 further comprising:

displaying network statistics associated with network flows; and

displaying a ranking of hosts in the network according to a network statistical measure.

21. The method of claim 20 wherein the network statistics are a number of bytes per second and packets per second of each type of protocol observed in the system.

22. A computer program product residing on a computer readable medium for producing a graphical user interface for an intrusion detection system, the computer program product comprising instructions for causing a computer to:

render a graphical user interface on an output device, the graphical user interface comprising:

a field that depicts a summary of anomalies identified as part of an event that is detected in a network, the summary indicating event severity details of the event;

an alert action region including a control to permit a user to snooze future alerts related to the event in the summary for a period of time.

23. The computer program product of claim 22 wherein the snooze control is selected based on event types and roles of hosts.

24. The graphical user interface of claim 22 further comprising instructions to render in the graphical user interface:

a control to allow a user to clear an alert if the alert appears on an overview page that provides an operator with an aggregated view of network status.

25. The computer program product of claim 22 wherein an event details region of the graphical user interface depicts anomalies that were used to classify the event.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2004
From: NAZZAL, ROBERT N.
To: MAZU NETWORKS, INC.
Reel/Frame 015526/0972 →
Continuity (1)
Related Publication 20040261030A1 · Dec 23, 2004